Technology

Apple Tightens Mac Full Disk Access as AI Agents Raise the Stakes

Martin HollowayPublished 12m ago3 min readBased on 4 sources
Reading level
Apple Tightens Mac Full Disk Access as AI Agents Raise the Stakes
source:apple.com

Apple is tightening controls around Full Disk Access on macOS, citing new risks from AI agents. The plan was detailed in reporting published on Oct. 2, 2026. TechCrunch

Full Disk Access is one of the broadest permissions on macOS. It lets an app read files, mail, messages and browsing history. Apple said it was designed to let backups work properly.

An app cannot give itself that access. Apple's developer documentation states that an app cannot gain Full Disk Access through an entitlement or code, and the user must grant it in System Settings. Apple Developer Documentation

Apple said AI agents have increased the risks of that grant. The concern is agents that work across the file system on a user's behalf, where one permission can expose mail, messages, browsing history and documents together. Apple said the risks will grow substantially as AI agents become increasingly capable and autonomous.

Apple also said some developers use Full Disk Access in ways that could put users at risk, exposing everything on their systems without users' full knowledge and understanding. Apple did not describe this as a flaw in the consent step alone. It described it as a mismatch between what users expect to share and how much data an agent can then read.

One example is already on the market. Meta's Muse AI on Mac optionally lets users enable Full Disk Access. The option is presented as user choice, which fits the existing System Settings flow.

The bar for that choice is changing. Apple said users who genuinely wish to grant an app Full Disk Access will be able to do so only with very explicit user action under the new controls. Apple has not described the exact interaction. The intent is to keep access for legitimate uses such as backups while adding friction against casual or poorly understood grants.

The move arrives alongside broader OS hardening. iOS 27 fixes 122 vulnerabilities and macOS 27 fixes over 200 vulnerabilities, with some of those fixes credited to AI systems such as Claude and Codex Security. ITnews

The broader context here is familiar to endpoint managers. Least privilege, the idea that each app gets only the access it needs, works well when apps stay separate. Agents blur that line by design, since their value comes from reading across silos and chaining actions. A file indexer needs broad read. A backup tool needs broad read. An agent that reads mail to find an invoice, then reads files to file it, then acts in the browser, needs all three at once.

In my view, Apple is adding friction in the right place. A full block would break legitimate administration and backup workflows. A single toggle invites overprovisioning, especially when the prompt appears during onboarding for an assistant that promises to handle everything. A more explicit grant pushes developers toward narrower file access where possible and forces a clearer value exchange where broad access is truly needed.

Worth flagging for enterprise and power-user workflows is the operational cost. Explicit grants complicate fleet deployment and remote support. They also create an incentive to request Full Disk Access by default rather than degrade gracefully. The long arc is still positive. Better scoping, clearer consent, and agents that can explain which stores they need and why would leave users with more capable automation and tighter control over mail, messages and files.